Welcome Guest. | Log In | Register | Membership Benefits

SenSage Achieves In Process Status For Stringent FIPS 140-2 Government Standard

To expedite the validation process, SenSage partnered with Corsec Security

May 31, 2011 | 03:00 PM | 


REDWOOD SHORES, CA – May 31, 2011 – SenSage, Inc., a leading provider of Security Information and Event Management (SIEM) systems, today announced that the SenSage CryptoCore Module has been placed on the Modules In Process List for the Federal Information Processing Standards Publications (FIPS) 140-2 Validation: Security Requirements for Cryptographic Modules. Since FIPS 140-2 validation is a requirement for any cryptographic product that will be used in a U.S. government agency network, this achievement provides strong validation for SenSage SIEM, log management and event data warehouse applications.

To expedite the FIPS 140-2 validation process, SenSage partnered with Corsec Security, Inc., a consulting firm with over 13 years experience in testing products for FIPS certification. “With the increased complexity of insider threats and advanced persistent threats, government agencies are looking beyond traditional SIEM technologies to address their sophisticated requirements for collecting, retaining, and analyzing sensitive data,” said Matthew Appler, CEO of Corsec Security. “SenSage directly addresses these needs, and this FIPS 140-2 validation is evidence of that.”

SenSage’s technology is also currently being evaluated under the National Information Assurance Partnership (NIAP) Common Criteria Evaluation and Validation Scheme for IT Security (CCEVS), with expected completion in the coming months.

“SenSage open security intelligence solutions address government compliance requirements and enable proactive information assurance missions,” said Joe Gottlieb, president and CEO of SenSage. “We are extremely proud of our role teaming with the Federal Government to facilitate compliance reporting and auditing while helping to protect our nation’s digital information, applications and infrastructure.”

“Government agencies need to filter vast amounts of security information and then drill down, across, through and around security exceptions to better understand security effectiveness and to prioritize security improvements,” explained Kirk Hanson, Senior Vice President of IT Solutions, Alvarez & Associates. “We are pleased to partner with SenSage to deliver what our customers need, and certainly, the FIPS 140-2 validation of the SenSage Private Encryption File System will provide users with a high degree of security, assurance, and dependability.”

The FIPS 140-2 standard, which is mandated by law in the U.S., is a joint effort by the National Institute of Standards and Technology (NIST) in the United States, and the Communications Security Establishment (CSEC), under the Canadian government. The FIPS standard is also currently being reviewed by ISO to become an international standard. The Cryptographic Module Validation Program (CMVP), headed by NIST, provides module and algorithm testing for FIPS 140-2, which applies to Federal agencies using validated cryptographic modules to protect sensitive government data in computer and telecommunication systems. FIPS 140-2 provides stringent third-party assurance of security claims on any product containing cryptography that may be purchased by a government agency. The In Process listing can be viewed at http://csrc.nist.gov/groups/STM/cmvp/documents/140-1/140InProcess.pdf.

About SenSage SenSage', Inc. helps organizations collect, store, analyze and interpret complex information to identify new threats, improve cyber-security defenses, and achieve industry and regulatory compliance.

Combining powerful data warehousing, scalable clustered multiprocessing and sophisticated analytics, SenSage serves our customers’ most advanced Security Information and Event Management (SIEM), log management, Call Detail Record (CDR) retention and retrieval and Continuous Controls Monitoring (CCM) use cases. SenSage systems are open to all event data types, scale to petabytes, minimize storage costs and perform sophisticated data analysis.

Hundreds of customers worldwide leverage patented Security Intelligence solutions from SenSage to identify, understand and counteract cyber-threats, fraud and compliance violations. SenSage partners include Cerner, Cisco, EMC, McAfee and SAP. For more information, visit www.Sensage.com, follow us on Twitter: @Sensage, and watch for us on www.youtube.com/Sensagetv.

About Corsec Security, Inc.

Corsec Security, Inc. specializes in helping companies navigate through the complex process of receiving FIPS 140-2 and Common Criteria (CC) certifications. Corsec’s consulting, document creation, and project management services deliver unmatched expertise in achieving government validation efforts at a firm, fixed price. Corsec partners with companies around the world to achieve local and international certification and to add security functionality to a wide range of products. Corsec minimizes the time, effort and money a vendor needs to invest in validation while ultimately maximizing the return on that investment. For further information, please visit www.corsec.com.

About Alvarez & Associates, LLC

Founded in 2004, Alvarez & Associates, LLC, (A&A) is a Washington DC based Information Technology company. In 2007, A&A was awarded the NASA SEWP lV Contract as one of only 6 Service Disabled Veteran Owned Small Businesses (SDVO/SB) prime contractors out of 38 prime contractors. The NASA SEWP (Solutions for Enterprise-Wide Procurement) GWAC (Government-Wide Acquisition Contract) allows Alvarez to provide the latest in Information Technology products to any Federal Government Agency, while helping that agency achieve its SDVO set-aside credit goals. For more information, please visit www.alvarezassociates.com.



Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

Dark Reading encourages readers to engage in spirited, healthy debate, including taking us to task. However, Dark Reading moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. Dark Reading further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
Subscribe to RSS



Security Monitoring Reports

report Fundamentals of User Activity Monitoring
Benchmarking normal activity and then monitoring for users who stray from that norm is an essential strategy for getting ahead of potential data and system breaches. But choosing the right tools is only part of the effort. Without sufficient training, efficient deployment and a good response plan, attackers could gain the upper hand.

report Does SIEM Make Sense For Your Company?
A security information and event management system serves as a repository for all the security alerts and logging systems from a firm's devices. But this can be overkill for a company that is understaffed or has overestimated its security information needs. In this report, we discuss 10 questions to ask yourself in determining whether SIEM makes sense for you--and how to pick the right system if it does.

report Monitoring Tools and Logs Make All The Difference
It's no longer a matter of "if" you get hacked, but when. In this special report, we take a look at ways to measure your security posture and the challenges that lie ahead with the emerging threat landscape.

Other reports from the Security Monitoring Tech Center:

Related Content

Security Management 2.0: Time to Replace Your SIEM?
Is it time? Are you waving the white flag? Has your first gen SIEM failed to meet expectations despite your investment? If you are questioning whether your existing product or service can get the job done, you are not alone. Read this Securosis white paper to learn how easy it can be to replace your SIEM with a next generation solution.

IT Executive Guide to Security Intelligence: Transitioning from SIEM to Total Security Intelligence
Read this whitepaper to learn how adopting a next generation SIEM solution provides security intelligence, to allow organizations to maintain comprehensive and cost-effective information security. Discover how security intelligence enables critical concerns in five key areas: Data silo consolidation, threat detection, fraud discovery, risk assessment/risk management, and regulatory compliance.

The Return on Security of QRadar: Improving Operational Efficiencies in Federal Government
In this study, IANS interviewed two Q1 Labs customers using QRadar to assess their Return On Security (ROS). The two customers were providers of service to the U.S. Government and had highly secure environments dealing with extremely sensitive data. The data yielded from the interviews showed substantial benefit to the organizations for the cost, both in money and staff time.

SANS What Works Webcast: Worldwide Retailer Boosts Privacy with Security Intelligence
A leading retailer with stores worldwide was seeking a more innovative tool to protect customer privacy and intellectual property. PCI compliance mandated log collection, but a vast number of different tools generated an overwhelming amount of log data, making it difficult for the small security team to review it effectively. The solution the company chose had to fit into a diverse network, provide intelligent reporting and offer a centralized management console.

Learn How Security Intelligence Can Help Combat WikiLeaks Stuxnet and Advanced Threats
WikiLeaks and Stuxnet have illustrated a few fundamental IT security issues that have underscored the need for Total Security Intelligence to counter advanced threats and to detect anomalous behavior. See how government and commercial organizations are using QRadar as an integral component of their IT security program to identify emerging threats based on context and situational awareness.




Featured Webcasts
Featured Whitepapers
Featured Reports